Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CWE-91 (XML注入(XPath盲注)) — Vulnerability Class 72

72 vulnerabilities classified as CWE-91 (XML注入(XPath盲注)). AI Chinese analysis included.

CWE-91, known as XML Injection or Blind XPath Injection, is a critical input validation weakness where applications fail to properly neutralize special characters within XML data. Attackers typically exploit this vulnerability by injecting malicious XPath queries into user-supplied input fields, manipulating the syntax of XML documents before they are processed. This allows adversaries to bypass authentication mechanisms, extract sensitive data, or alter application logic without receiving direct error feedback, hence the "blind" nature of the attack. To prevent such exploits, developers must rigorously sanitize all user inputs by escaping or removing dangerous characters like quotes and angle brackets. Additionally, employing parameterized queries or using secure XML parsing libraries that enforce strict schema validation ensures that user data is treated strictly as content rather than executable code, effectively neutralizing the injection vector.

MITRE CWE Description
The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system. Within XML, special elements could include reserved words or characters such as "<", ">", """, and "&", which could then be used to add new data or modify XML syntax.
Common Consequences (1)
Confidentiality, Integrity, Availability Execute Unauthorized Code or Commands, Read Application Data, Modify Application Data
Mitigations (1)
Implementation Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range…
CVE ID Title CVSS Severity Published
CVE-2026-103044 EasyTimeline should not serve image maps as application/xml — Mediawiki - EasyTimeline extension - - 2026-09-29
CVE-2026-76979 XML Injection vulnerability — ManageEngine OpManager 7.7 High 2026-09-23
CVE-2026-65124 NVIDIA Linux Infrastructure Controller XML注入漏洞 — Infrastructure Controller 5.9 Medium 2026-09-22
CVE-2026-89247 WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php — AVideo 6.1 Medium 2026-09-11
CVE-2026-2310 IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data — webMethods Integration Server 7.8 High 2026-09-10
CVE-2026-83618 xmldom: requireWellFormed DocType publicId/systemId validation is bypassable via an embedded line terminator — xmldom 8.7 High 2026-09-01
CVE-2026-83617 xmldom: requireWellFormed element/attribute name validation is bypassable via an embedded line terminator — xmldom 8.7 High 2026-09-01
CVE-2026-83616 xmldom: Processing Instruction Target Injection Bypasses requireWellFormed — xmldom 8.7 High 2026-09-01
CVE-2026-83609 xmldom: Creation-time XML Name/QName validation is bypassable via an embedded line terminator, allowing injection on the default serialization path — xmldom 8.7 High 2026-09-01
CVE-2026-83608 xmldom: DocType `name` Injection Bypasses requireWellFormed — xmldom 8.7 High 2026-09-01
CVE-2026-83607 xmldom: Element name injection via createElement() bypasses requireWellFormed — xmldom 8.7 High 2026-09-01
CVE-2026-83605 xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed — xmldom 8.7 High 2026-09-01
CVE-2026-48590 Element and Attribute Names Injected Verbatim into XML Output in xml_builder — xml_builder 2.1 Low 2026-08-21
CVE-2026-47080 CDATA Section Breakout via Unsanitised ]]> in xml_builder — xml_builder 2.1 Low 2026-08-21
CVE-2026-24329 Wildfly-core: wildfly core: denial of service via malformed payload injection by an authenticated administrative user. — Red Hat Fuse 7 4.9 Medium 2026-08-11
CVE-2026-59728 @astrojs/rss: XML Injection via Unescaped RSS Feed Fields — astro 4.3 Medium 2026-07-27
CVE-2026-15037 XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization — Qt 2.9 Low 2026-07-23
CVE-2026-55789 Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers — logto 8.5 High 2026-07-10
CVE-2026-46490 samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions — samlify - - 2026-06-08
CVE-2026-47273 pam_usb: XPath injection via PAM-supplied identifiers in pam_usb configuration queries — pam_usb 6.5 Medium 2026-05-27
CVE-2026-44664 fast-xml-builder: Comment Value bypass regex — fast-xml-builder 6.1 Medium 2026-05-13
CVE-2026-44665 fast-xml-builder: Attribute values with unwanted quotes can bypass malicious or unwanted attributes — fast-xml-builder 6.1 Medium 2026-05-13
CVE-2026-41650 fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters — fast-xml-parser 6.1 Medium 2026-05-07
CVE-2026-41675 xmldom: XML node injection through unvalidated processing instruction serialization — xmldom 8.7 High 2026-05-07
CVE-2026-41674 xmldom: XML injection through unvalidated DocumentType serialization — xmldom 8.7 High 2026-05-07
CVE-2026-41672 xmldom: XML node injection through unvalidated comment serialization — xmldom 8.7 High 2026-05-07
CVE-2026-27693 traccar allows XML injection in KML and GPX exports — traccar 5.4 Medium 2026-05-05
CVE-2026-32870 Kirby has XML injection in its XML creator toolkit — kirby 7.1AI High AI 2026-04-24
CVE-2026-34601 xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion — xmldom 7.5 High 2026-04-02
CVE-2026-28770 XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interface Version 101 — SFX Series SuperFlex Satellite Receiver Web management interface 5.4AI Medium AI 2026-03-04

Vulnerabilities classified as CWE-91 (XML注入(XPath盲注)) represent 72 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.